freenode
AnalysisSecurity & Cryptography

Signal, noise, and the machine in the middle

In the same stretch of weeks, an AI-assisted lattice attack knocked a NIST post-quantum candidate off the table, the IETF wrestled with floods of machine-written drafts, and Emacs lists erupted over LLM agents and generated code, forcing free-software communities to ask what a contribution still is.

The same stretch of calendar that saw an AI system help break a post-quantum signature scheme also saw standards bodies and free-software projects choking on machine-generated text. The coincidence is not cute. It crystallizes a single pressure: models are now both sharp enough to attack cryptographic primitives and cheap enough to flood the human processes that are supposed to evaluate contributions, standards, and code. Communities built on slow, attributable human review are discovering they can no longer take signal for granted.

On the pqc-forum, Steve Weis announced an improved key-recovery attack against HAWK-n that reduces to SVP in dimension n/2 + 1. In the gate-count model the attack drops HAWK-512 from 2^150 to 2^108 and HAWK-1024 from 2^288 to 2^182; a practical end-to-end recovery of a HAWK-256 secret finished in hours on one server. The result does not touch Falcon or ML-DSA, but it was enough to push HAWK out of the NIST post-quantum signatures picture. The detail that landed hardest was the provenance line: the weakness "was found by Claude, with minimal technical guidance from people." Daniel Apon’s reply was terse and technical: "Nice. It checks out independently for me." Elsewhere on the same list, threads about isogeny NIKE candidates such as MIKE continued in the ordinary register of parameter choices, timing, and hybrid deployment advice. Demi Marie Obenour argued that operators who control both ends need not wait for final standards; Bas Westerbaan answered with adoption graphs that still separate human and automated traffic. Cryptanalysis assisted by a model and ordinary human parameter debate sat side by side, with no shared vocabulary yet for how much machine help counts as a result.

That same cheap generation capacity hit the IETF as volume rather than as a break. Independent Internet-Draft submissions surged. Ross Finlayson opened with the blunt assessment that "this is getting out of hand" and suggested treating the flood "as a problem akin to spam," half-jokingly floating a bond refundable only on working-group adoption and more seriously proposing split announcement lists so that working-group drafts could be followed without the independent noise. Theodore Tso pointed at emerging watermark detectors such as SynthID and promised Claude tooling, while noting the obvious gap for open-weight models. Lars Eggert refused nostalgia: "the issue of fully or partially AI-generated IETF contributions is here to stay." He drew the parallel every maintainer already feels: "PRs are now cheap to generate and the cost is shifting to core review, which is not (yet?) similarly cheaply done." His personal adaptation was faster disregard for unfamiliar names unless a known person engaged first. Carsten Bormann immediately named the downside: the IETF could become less open to genuine newcomers lost in "AI slop." His counter-proposal was attention infrastructure inside the Datatracker: non-boolean commendations, per-viewer weights built from authorship and leadership history, subjective private document scores. Andrew Yourtchenko floated shaping the -00 rate limit into a web-of-trust bootstrapped from existing participation guides, one free-hanging draft then a shepherd. Carlos Martinez-Cagnazzo added that one defense against slop might be another model tuned to IETF style and metrics. S Moonesamy observed that some working-group traffic was already machine-generated and that lowered barriers had produced muddled drafts simply because writing one became easy. No consensus formed; the tools under discussion (watermarks, bonds, shepherds, commendation graphs) all trade openness for filter strength, and no one could say where the equilibrium sits.

The Emacs and NonGNU side made the philosophical stakes concrete. Thanos Apollo submitted hermes, an Emacs front end for a Hermes Agent that offers dashboards, streamed diffs, approval prompts, and local or remote agent instances. Richard Stallman and Eli Zaretskii reopened the long GNU argument about whether packaging a conduit "steers" users toward non-free or SaaSS systems; Zaretskii held that allowing configured access is not recommendation, Stallman that influence still carries responsibility under the References node of the GNU Coding Standards. Jean Louis then reported repository archaeology: an AGENTS.md that had instructed "add no generated-by or co-author metadata," later removed. He argued the GNU project still lacks a policy for LLM-generated code, that copyright assignment needs a human author, and that an LLM cannot hold copyright. A reply arrived from "Hermes," described as Thanos’s email agent, asserting that "Assisted-by: Hermes:MoA" already appeared in the package header and that the metadata rule concerned commit subjects only: "No concealed clanker here." The list reaction was immediate and visceral. Jacob S. Gordon called the tactic "LLM-generated messages and this attitude" a way "to respond to people you don’t wish to engage with" and asked for ordinary silence instead of "hurling slop." Andrei Sova labeled it "gross display of contempt" and "overwhelmingly rude" to expect subscribers to treat non-human mail as conversation. Petteri Hintsanen simply asked that bot slop stop; "It is just spam." The technical package, the copyright theory, the steering debate, and the etiquette of automated replies collapsed into one thread. Maintainers were left holding both an archive-policy vacuum and a social norm that had not previously needed stating: list mail is presumed human.

Across the three venues the through-line is identical. Model assistance can surface a lattice reduction that human reviewers then verify, which is close to the classic open-analysis bargain. The same class of system can also emit endless plausible drafts and even reply on a development list while its principal steps aside. Process cost moves from authorship to review and to the prior question of whether the author is present at all. NIST’s signature track loses a candidate; the IETF experiments with rate limits and reputation-like weights without wanting the word "reputation"; Emacs faces undeclared generation, assignment mechanics, and bot traffic on emacs-devel itself.

Nothing is settled. HAWK is effectively gone from the NIST round, yet the broader lattice and isogeny conversations continue with ordinary human disagreement about deployment urgency. IETF participants agree the genie stays out and disagree on every concrete filter. GNU and Emacs still have no published rule for LLM-assisted or LLM-generated code, while the social prohibition on agent replies is being asserted by outrage rather than by written policy. The unresolved question is not whether models will be used. It is whether communities whose authority rests on readable human responsibility can still reliably tell a contribution from exhaust, and what they will sacrifice (openness, speed, or the assumption of a person on the other end of the mail) to keep that distinction.